feat(k8s): allow to set security contexts for worker and apps

Signed-off-by: Pascal Sthamer <10992664+P4sca1@users.noreply.github.com>
This commit is contained in:
Pascal Sthamer
2025-04-17 09:59:37 +02:00
parent 319c939c1f
commit 9fa02c15b1
6 changed files with 442 additions and 55 deletions
+46 -20
View File
@@ -57,9 +57,13 @@ var logsDisabled = os.Getenv("SHUFFLE_LOGS_DISABLED")
var cleanupEnv = strings.ToLower(os.Getenv("CLEANUP"))
var swarmNetworkName = os.Getenv("SHUFFLE_SWARM_NETWORK_NAME")
var dockerApiVersion = strings.ToLower(os.Getenv("DOCKER_API_VERSION"))
var appServiceAccountName = os.Getenv("SHUFFLE_APP_SERVICE_ACCOUNT_NAME")
// Kubernetes settings
var appServiceAccountName = os.Getenv("SHUFFLE_APP_SERVICE_ACCOUNT_NAME")
var appPodSecurityContext = os.Getenv("SHUFFLE_APP_POD_SECURITY_CONTEXT")
var appContainerSecurityContext = os.Getenv("SHUFFLE_APP_CONTAINER_SECURITY_CONTEXT")
var kubernetesNamespace = os.Getenv("KUBERNETES_NAMESPACE")
var executionCount int64
var baseimagename = os.Getenv("SHUFFLE_BASE_IMAGE_NAME")
@@ -503,6 +507,28 @@ func deployk8sApp(image string, identifier string, env []string) error {
"app.kubernetes.io/instance": name,
}
// Parse security contexts from env
var podSecurityContext *corev1.PodSecurityContext
var containerSecurityContext *corev1.SecurityContext
if len(appPodSecurityContext) > 0 {
podSecurityContext = &corev1.PodSecurityContext{}
err = json.Unmarshal([]byte(appPodSecurityContext), podSecurityContext)
if err != nil {
log.Printf("[ERROR] Failed to unmarshal app pod security context: %v", err)
return fmt.Errorf("failed to unmarshal app pod security context: %v", err)
}
}
if len(appContainerSecurityContext) > 0 {
containerSecurityContext = &corev1.SecurityContext{}
err = json.Unmarshal([]byte(appContainerSecurityContext), containerSecurityContext)
if err != nil {
log.Printf("[ERROR] Failed to unmarshal app container security context: %v", err)
return fmt.Errorf("failed to unmarshal app container security context: %v", err)
}
}
// pod := &corev1.Pod{
// ObjectMeta: metav1.ObjectMeta{
// Name: podName,
@@ -596,13 +622,15 @@ func deployk8sApp(image string, identifier string, env []string) error {
Spec: corev1.PodSpec{
Containers: []corev1.Container{
{
Name: value,
Image: image,
Env: buildEnvVars(envMap),
Name: value,
Image: image,
Env: buildEnvVars(envMap),
SecurityContext: containerSecurityContext,
},
},
DNSPolicy: corev1.DNSClusterFirst,
ServiceAccountName: appServiceAccountName,
SecurityContext: podSecurityContext,
},
},
},
@@ -917,7 +945,7 @@ func deployApp(cli *dockerclient.Client, image string, identifier string, env []
// Add more volume binds if possible
if len(volumeBinds) > 0 {
// Only use mounts, not direct binds
// Only use mounts, not direct binds
hostConfig.Binds = []string{}
hostConfig.Mounts = []mount.Mount{}
for _, bind := range volumeBinds {
@@ -931,7 +959,7 @@ func deployApp(cli *dockerclient.Client, image string, identifier string, env []
sourceFolder := bindSplit[0]
destinationFolder := bindSplit[1]
readOnly := false
readOnly := false
if len(bindSplit) > 2 {
mode := bindSplit[2]
if mode == "ro" {
@@ -940,9 +968,9 @@ func deployApp(cli *dockerclient.Client, image string, identifier string, env []
}
builtMount := mount.Mount{
Type: mount.TypeBind,
Source: sourceFolder,
Target: destinationFolder,
Type: mount.TypeBind,
Source: sourceFolder,
Target: destinationFolder,
ReadOnly: readOnly,
}
@@ -1853,18 +1881,18 @@ func executionInit(workflowExecution shuffle.WorkflowExecution) error {
}
}
// Validates RERUN of single actions
// Identified by:
// Validates RERUN of single actions
// Identified by:
// 1. Predefined result from previous exec
// 2. Only ONE action
// 3. Every predefined result having result.Action.Category == "rerun"
/*
if len(workflowExecution.Workflow.Actions) == 1 && len(workflowExecution.Results) > 0 {
finished := shuffle.ValidateFinished(ctx, extra, workflowExecution)
if finished {
return nil
if len(workflowExecution.Workflow.Actions) == 1 && len(workflowExecution.Results) > 0 {
finished := shuffle.ValidateFinished(ctx, extra, workflowExecution)
if finished {
return nil
}
}
}
*/
nextActions = append(nextActions, startAction)
@@ -1954,7 +1982,6 @@ func executionInit(workflowExecution shuffle.WorkflowExecution) error {
//log.Printf("Successfully downloaded and built %s", image)
}
visited := []string{}
executed := []string{}
environments := []string{}
@@ -3777,7 +3804,7 @@ func checkStandaloneRun() {
if !strings.Contains(backendUrl, "http") {
log.Printf("[ERROR] Backend URL should start with http:// or https://")
return
}
// Format:
@@ -3851,7 +3878,7 @@ func checkStandaloneRun() {
continue
}
// This is to handle reruns of SINGLE actions
// This is to handle reruns of SINGLE actions
if result.Action.Category == "rerun" {
newResults = append(newResults, result)
continue
@@ -3905,7 +3932,6 @@ func checkStandaloneRun() {
log.Printf("\n\n\n[DEBUG] Finished resetting execution %s. Body: %s. Starting execution.\n\n\n", newresp.Status, string(body))
}
// Initial loop etc